eb5465f4e2
Enhanced the structure of the line for clearer instruction |
||
---|---|---|
.. | ||
Artifacts | ||
Images | ||
Modules | ||
Package | ||
README.md |
README.md
Welcome to Microsoft Sentinel Training Lab
Introduction
These labs help you get ramped up with Microsoft Sentinel and provide hands-on practical experience for product features, capabilities, and scenarios.
The lab deploys an Microsoft Sentinel workspace and ingests pre-recorded data to simulate scenarios that showcase various Microsoft Sentinel features. You should expect very little or no cost at all due to the size of the data (~10 MBs) and the fact that Microsoft Sentinel offers a 30-day free trial.
Prerequisites
To deploy Microsoft Sentinel Trainig Lab, you must have a Microsoft Azure subscription. If you do not have an existing Azure subscription, you can sign up for a free trial here.
Last release notes
- Version 1.0 - Microsoft Sentinel Training Lab
Getting started
Below you can see all the modules that are part of this lab. Although in general they can be completed in any order, you must start with Module 1 as this deploys the lab environment itself.
Modules
Module 1 – Setting up the environment
- The Microsoft Sentinel workspace
- Deploy the Microsoft Sentinel Training Lab Solution
- Configure Microsoft Sentinel Playbook
- Enable Azure Activity data connector
- Enable Azure Defender data connector
- Enable Threat Intelligence TAXII data connector
- Analytics Rules overview
- Enable Microsoft incident creation rule
- Review Fusion Rule (Advanced Multistage Attack Detection)
- Create custom analytics rule
- Review resulting security incident
Module 4 – Incident Management
- Review Microsoft Sentinel incident tools and capabilities
- Handling Incident "Sign-ins from IPs that attempt sign-ins to disabled accounts"
- Handling "Solorigate Network Beacon" incident
- Hunting for more evidence
- Add IOC to Threat Intelligence
- Handover incident
- Hunting on a specific MITRE technique
- Bookmarking hunting query results
- Promote a bookmark to an incident